Skip to content

"try" portion of site is insecure #12

@tylerni7

Description

@tylerni7

So I was playing with http://dreal.github.io/try/ and realized the server on the back-end ( gauss.modck.cs.cmu.edu ) basically just exposes the ability to have clients execute arbitrary code on it... (meaning just unix shell commands, not just dReal SMT proofs)

This is not a good idea, and someone should probably lock that down....

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions